Impact
A bug in the Linux kernel’s RAID1 driver causes an Oops when a new redundant disk is added to an existing RAID1 array that has serialization policy enabled. The driver skips initializing a required field, which the wait_for_serialization routine later dereferences, leading to a local kernel panic. This results in a denial‑of‑service condition for the host system until a reboot or other recovery. The weakness is an example of improper initialization of a critical data structure.
Affected Systems
The vulnerability affects only the Linux kernel. It was observed with kernel version 7.1.3 when adding a new rdev to an existing RAID1 array with the serialize_policy attribute set to 1. Older kernel releases prior to the patch do not exhibit the symptom, and the issue is mitigated in later kernel releases where the initialization path has been corrected.
Risk and Exploitability
The EPSS score is reported less than 1%, indicating a very low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. The attack requires privileged local access to modify a RAID configuration, so the most likely exploitation path is through direct interaction with the host. The defect causes a crash rather than privilege escalation or data exfiltration, but an attacker who can trigger the bug can cause a denial‑of‑service attack on the affected system.
OpenCVE Enrichment
Debian DLA
Debian DSA